Kiosk mode fails after reboot: "Draw Over Other Apps" permission reset by device firmware
Android
When certain device firmware resets the "Draw Over Other Apps" permission on every reboot, Esper-managed kiosk devices fail to launch correctly after restart — displaying a blank screen or falling through to the Android home screen instead of the kiosk interface.
Why this happens
Kiosk mode requires the SYSTEM_ALERT_WINDOW ("Draw Over Other Apps") permission to display the kiosk overlay above all other apps. On some device models, a firmware defect clears this permission during the reboot sequence — even though the Esper Agent was correctly granted the permission during provisioning. Because this is caused by the device firmware, not Esper, the permanent fix requires a firmware update from your device manufacturer.
Steps
-
Confirm the permission is being reset on the device.
On an affected device, go to Settings → Apps → Esper Agent → Permissions → Draw Over Other Apps and note whether the permission is set to Allowed. Reboot the device, return to the same path, and check again. If the permission shows as Denied after reboot, the firmware is resetting it on every restart, which is the root cause of the kiosk failure. -
Collect device and firmware details from the Esper Console.
In the Esper Console, go to Devices & Groups → [Device Name] → Device Details → Software Info. For each affected device, record the serial number or IMEI, device model, and firmware build number. You will need this information when contacting your device manufacturer. -
Submit a bug report to your device manufacturer.
Contact your device manufacturer's support team (for example, Azulle, Brightstar, or your ODM) and include the following:- The device models, serial numbers, and firmware build numbers collected in Step 2.
- A description of the defect: "The
SYSTEM_ALERT_WINDOW(Draw Over Other Apps) permission is reset to Denied on every reboot, even though it was granted during device provisioning." - Steps to reproduce: enroll the device in kiosk mode with Esper, confirm Draw Over Other Apps is Allowed, reboot the device, and confirm the permission has reset to Denied.
- A request for a firmware patch that preserves runtime permissions across reboots, and a confirmed release timeline.
-
Deploy the corrected firmware once your manufacturer releases it.
When a patched firmware build is available, deploy it using one of the following methods:- Via Esper Console: Go to Esper Software Updates, select the affected devices or group, and deploy the new firmware build.
- Via manufacturer OTA: Use your device manufacturer's own OTA update mechanism to push the firmware directly to affected devices.
- Verify: After the firmware update is applied, reboot an affected device. The kiosk should launch automatically within the normal boot sequence. Then go to Settings → Apps → Esper Agent → Permissions → Draw Over Other Apps and confirm the permission remains Allowed after the reboot. Check the Activity Feed in the Esper Console for that device to confirm no permission-related errors appear.
If this doesn't resolve it
If your device manufacturer is unresponsive, cannot confirm a firmware fix timeline, or if this permission-reset behavior appears on device models not previously affected, contact Esper Support. When you reach out, provide the device models, firmware build numbers, and the manufacturer support case number if you have one — this significantly speeds up the investigation.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments